Virus Malware defence support ??

Bonjour,
Je viens de me faire attaquer pas un virus qui s'appelle malware defence systeme .. J'ai des icones qui apparaissent systematiqument et qui me dise que mon ordi est envahi etc etc ..

J'ai telecharger : Hijackthis .. et voici le rapport :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:18:34, on 01/01/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\MSI\BToes Logiciel Bluetooth\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\iexplore.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\dzenis\LOCALS~1\Temp\settdebugx.exe
C:\Program Files\Malware Defense\mdefense.exe
C:\Program Files\MSI\BToes Logiciel Bluetooth\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\iPod\bin\iPodService.exe
C:\DOCUME~1\dzenis\LOCALS~1\Temp\wscsvc32.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\dzenis\Bureau\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iexplore] C:\WINDOWS\iexplore.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [settdebugx.exe] C:\DOCUME~1\dzenis\LOCALS~1\Temp\settdebugx.exe
O4 - HKCU\..\Run: [Malware Defense] "C:\Program Files\Malware Defense\mdefense.exe" -noscan
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'Default user')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\MSI\BToes Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game07.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\MSI\BToes Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 7249 bytes

Si quelqu'un peut m'aider sa serait super sympa merci !
Configuration: Windows XP Internet Explorer 7.0

20 réponses

  1. Contributeur sécurité
    bonjour

    comme tous le monde...

    • Télécharge Random's System Information Tool (RSIT) de Random/Random.

    http://images.malwareremoval.com/random/RSIT.exe

    • Enregistre le sur ton Bureau.

    • Double clique sur RSIT.exe pour lancer l'outil.

    • Clique sur "Continue" à l'écran Disclaimer.

    • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

    et tu devras accepter la licence.

    • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

    Les rapports se trouvent à cet endroit:
    C:\rsit\info.txt
    C:\rsit\log.txt
    0
    1. Je n'arrive pas a telcharger le programme Télécharge Random's System Information Tool (RSIT) de Random/Random.. il me marque que la page n'existe pas ...
      0
      1. bonsoir
        il y a des personnes qui sont beaucoup plus qualifiées que moi.
        vous n'avez pas antivirus?
        essayer de télécharger un antivirus qui fait le nettoyage.
        moi j'ai ClamXav pour Mac mais je ne sais pas si il existe pour windows.
        vous auriez un Mac vous seriez plus tranquille.
        à bientôt.
        0
        1. Non toujours pas.. sa m'arrive souvent de pas pouvoir telecharger des pogramme comme msn par exemple mais bon la n'est pas la question... t'aurais un autre programme s'il te plait ?
          0
          1. Contributeur sécurité
            on va passer l'étape RSIT

            Attention, avant de commencer, lit attentivement la procédure, et imprime la

            Télécharge ComboFix de sUBs en le renommant MDG.exe avant de l'enregistrer sur ton Bureau :
            http://download.bleepingcomputer.com/sUBs/ComboFix.exe

            /!\ Déconnecte-toi du net et DESACTIVES TOUTES LES DEFENSES, antivirus et antispyware y compris /!\

            ---> Double-clique sur ComboFix.exe
            Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

            SURTOUT INSTALLES LA CONSOLE DE RECUPERATION

            ---> Mets-le en langue française F
            Tape sur la touche 1 (Yes) pour démarrer le scan.

            Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

            En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

            Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

            /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

            Note : Le rapport se trouve également là : C:\ComboFix.txt

            0
            1. ComboFix 09-12-31.A1 - dzenis 01/01/2010 18:18:01.1.1 - x86
              Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.511.355 [GMT 1:00]
              Lancé depuis: c:\documents and settings\dzenis\Bureau\MDG.exe

              AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
              .

              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
              .

              c:\docume~1\dzenis\LOCALS~1\Temp\wscsvc32.exe
              c:\documents and settings\All Users.WINDOWS\Bureau\nudetube.com.lnk
              c:\documents and settings\All Users.WINDOWS\Bureau\pornotube.com.lnk
              c:\documents and settings\All Users.WINDOWS\Bureau\youporn.com.lnk
              c:\program files\Malware Defense
              c:\program files\Malware Defense\help.ico
              c:\program files\Malware Defense\md.db
              c:\program files\Malware Defense\mdefense.exe
              c:\program files\Malware Defense\mdext.dll
              c:\program files\Malware Defense\uninstall.exe
              c:\windows\EXPL0RER.exe
              c:\windows\iexplore.exe
              c:\windows\system32\blat.exe
              c:\windows\system32\drivers\fad.sys
              c:\windows\system32\drivers\H8SRTilrxubrqoi.sys
              c:\windows\system32\H8SRTbnreexmwvb.dll
              c:\windows\system32\H8SRTfhexjoeued.dat
              c:\windows\system32\H8SRTxvpsiwuymw.dll
              c:\windows\system32\H8SRTyjplfdlnts.dll
              c:\windows\system32\msconfig.exe
              c:\windows\system32\srcr.dat

              .
              ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
              .

              -------\Service_H8SRTd.sys
              -------\Legacy_H8SRTd.sys

              ((((((((((((((((((((((((((((( Fichiers créés du 2009-12-01 au 2010-01-01 ))))))))))))))))))))))))))))))))))))
              .

              2010-01-01 15:53 . 2009-12-03 15:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
              2010-01-01 15:53 . 2010-01-01 15:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
              2010-01-01 15:53 . 2010-01-01 15:53 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
              2010-01-01 15:53 . 2009-12-03 15:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
              2010-01-01 11:59 . 2010-01-01 11:59 874 ----a-w- c:\windows\system32\krl32mainweq.dll
              2010-01-01 11:58 . 2010-01-01 11:58 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
              2009-12-22 22:12 . 2009-12-27 12:15 -------- d-----w- c:\documents and settings\dzenis\Tracing
              2009-12-05 15:15 . 2004-08-03 22:08 17024 ----a-w- c:\windows\system32\drivers\usbohci.sys
              2009-12-05 15:09 . 2004-08-03 21:29 1897408 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
              2009-12-05 15:09 . 2004-08-19 15:09 4274816 ----a-w- c:\windows\system32\nv4_disp.dll

              .
              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
              .
              2009-12-26 16:00 . 2008-10-04 18:11 -------- d-----w- c:\documents and settings\dzenis\Application Data\Image Zone Express
              2009-12-22 22:27 . 2001-08-28 14:00 48616 ----a-w- c:\windows\system32\perfc00C.dat
              2009-12-22 22:27 . 2001-08-28 14:00 367658 ----a-w- c:\windows\system32\perfh00C.dat
              2009-10-23 17:09 . 2009-10-23 17:09 4096 ----a-w- c:\windows\system32\01.tmp
              2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
              2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
              2007-02-25 10:06 . 2009-05-20 11:56 122880 --sha-r- c:\windows\system32\blat.dll
              2009-03-21 14:20 . 2004-08-19 16:09 174326 --sha-r- c:\windows\system32\umzqpjlg.dll
              .

              ------- Sigcheck -------

              [-] 2008-04-14 . E17C85D5B5CF477638433B851A98499E . 1571840 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\sfcfiles.dll
              [-] 2004-11-28 14:36 . AB3D62010AF342203FFA60C2D94DBC68 . 8704 . . [1] . . c:\windows\system32\sfcfiles.dll
              .
              ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
              .
              .
              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
              REGEDIT4

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
              "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-19 110592]
              "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-08-31 185896]
              "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
              "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-13 136600]
              "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]

              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
              "LSD_III"="c:\windows\LSD\end.cmd" [2005-07-14 2310]
              "tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-19 44544]

              c:\documents and settings\dzenis\Menu D‚marrer\Programmes\D‚marrage\
              OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

              c:\documents and settings\All Users.WINDOWS\Menu D‚marrer\Programmes\D‚marrage\
              BTTray.lnk - c:\program files\MSI\BToes Logiciel Bluetooth\BTTray.exe [2005-3-29 569405]
              HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
              "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
              "c:\\WINDOWS\\system32\\sessmgr.exe"=
              "c:\\Program Files\\iTunes\\iTunes.exe"=

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
              "3162:TCP"= 3162:TCP:bamuniih

              R3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [24/11/2008 12:01 167424]
              S2 fhvagofvw;Windows Monitor;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 17:10 14336]
              S3 ducqrhuf;ducqrhuf;c:\windows\system32\01.tmp [23/10/2009 18:09 4096]
              S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [11/09/2008 16:35 13352]
              S3 jbygyv;jbygyv;c:\windows\system32\01.tmp [23/10/2009 18:09 4096]
              S3 mgodujgxs;mgodujgxs;c:\windows\system32\01.tmp [23/10/2009 18:09 4096]
              S3 MTK;Media Technology Kernel Driver;c:\windows\system32\Drivers\mtk.sys --> c:\windows\system32\Drivers\mtk.sys [?]
              S3 tsmrbqkn;tsmrbqkn;\??\c:\windows\system32\02.tmp --> c:\windows\system32\02.tmp [?]
              S3 zypugiejz;zypugiejz;c:\windows\system32\01.tmp [23/10/2009 18:09 4096]

              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
              fhvagofvw
              .
              Contenu du dossier 'Tâches planifiées'

              2009-12-29 c:\windows\Tasks\AppleSoftwareUpdate.job
              - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

              2009-12-31 c:\windows\Tasks\HPpromotions journeysoftware.job
              - c:\program files\hp\digital imaging\bin\hp promotions\journeysoftware\HPpromo.exe [2005-04-22 15:36]

              2010-01-01 c:\windows\Tasks\User_Feed_Synchronization-{0ACA7517-FC6A-4F37-8251-C1F37294BF46}.job
              - c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
              .
              .
              ------- Examen supplémentaire -------
              .
              uStart Page = hxxp://google.fr/
              IE: Envoyer à &Bluetooth - c:\program files\MSI\BToes Logiciel Bluetooth\btsendto_ie_ctx.htm
              DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game07.zylom.com/activex/zylomgamesplayer.cab
              FF - ProfilePath - c:\documents and settings\dzenis\Application Data\Mozilla\Firefox\Profiles\740kt1mv.default\
              FF - prefs.js: browser.search.selectedEngine - Bing
              FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
              FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?mkt=fr-FR&form=MIMWA5&q=
              FF - prefs.js: network.proxy.type - 1
              .
              - - - - ORPHELINS SUPPRIMES - - - -

              HKCU-Run-MsnMsgr - c:\program files\Windows Live\Messenger\MsnMsgr.Exe
              HKCU-Run-Malware Defense - c:\program files\Malware Defense\mdefense.exe
              AddRemove-Malware Defense - c:\program files\Malware Defense\Uninstall.exe

              **************************************************************************

              catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2010-01-01 18:35
              Windows 5.1.2600 Service Pack 2 NTFS

              Recherche de processus cachés ...

              Recherche d'éléments en démarrage automatique cachés ...

              Recherche de fichiers cachés ...

              Scan terminé avec succès
              Fichiers cachés: 0

              **************************************************************************

              [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ducqrhuf]
              "ImagePath"="\??\c:\windows\system32\01.tmp"

              [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\jbygyv]
              "ImagePath"="\??\c:\windows\system32\01.tmp"

              [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mgodujgxs]
              "ImagePath"="\??\c:\windows\system32\01.tmp"

              [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tsmrbqkn]
              "ImagePath"="\??\c:\windows\system32\02.tmp"

              [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zypugiejz]
              "ImagePath"="\??\c:\windows\system32\01.tmp"

              [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fhvagofvw]
              "ServiceDll"="c:\windows\system32\umzqpjlg.dll"
              .
              --------------------- DLLs chargées dans les processus actifs ---------------------

              - - - - - - - > 'explorer.exe'(2916)
              c:\windows\system32\ieframe.dll
              c:\windows\system32\webcheck.dll
              .
              ------------------------ Autres processus actifs ------------------------
              .
              c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              c:\program files\MSI\BToes Logiciel Bluetooth\bin\btwdins.exe
              c:\program files\Java\jre6\bin\jqs.exe
              c:\program files\OpenOffice.org 3\program\soffice.exe
              c:\program files\OpenOffice.org 3\program\soffice.bin
              c:\program files\iPod\bin\iPodService.exe
              c:\program files\Java\jre6\bin\jucheck.exe
              .
              **************************************************************************
              .
              Heure de fin: 2010-01-01 18:45:06 - La machine a redémarré
              ComboFix-quarantined-files.txt 2010-01-01 17:44

              Avant-CF: 27 440 939 008 octets libres
              Après-CF: 34 635 329 536 octets libres

              - - End Of File - - D894BBA9792C6438F43072C060401F1B
              0
              1. ca veut toujours pas telecharger... :(
                0
                1. Contributeur sécurité
                  Téléchargez MalwareByte's Anti-Malware

                  http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                  . Enregistres le sur le bureau
                  . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                  . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                  . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
                  . Une fois la mise à jour terminé
                  . Rend-toi dans l'onglet, Recherche
                  . Sélectionnes Exécuter un examen complet
                  . Cliques sur Rechercher
                  . Le scan démarre.
                  . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                  . Cliques sur Ok pour poursuivre.
                  . Si des malwares ont été détectés, clique sur Afficher les résultats
                  . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                  . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                  . Rends toi dans l'onglet rapport/log
                  . Tu cliques dessus pour l'afficher, une fois affiché
                  . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
                  . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                  . tu cliques droit dans le cadre de la reponse et coller

                  Si tu as besoin d'aide regarde ces tutoriels :
                  Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                  http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
                  0
                  1. pffff je n'arrive pas a le telcharger sa me fait que interet explorere ne peut pas ouvrir cette page comme si je n'etait pas connecté sur le net !
                    0
                    1. Nan mais laisse tomber, c'est quand je click sur telcharger que sa me met une page " immpossible douvire etc etc " comme quand je ne suis pas connecté sur le net.
                      0
                      1. Contributeur sécurité
                        on va en essayer un autre

                        Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                        ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
                        http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

                        double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                        coche la case "creer une icone sur le bureau"

                        une fois terminée , clic sur "terminer" et le programme se lancer seul

                        choisis la langue puis choisis l'option 1 = Mode Recherche

                        ▶ laisse travailler l'outil

                        à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                        un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                        ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                        tu peux supprimer le rapport catchme.log de ton bureau maintenant.

                        0
                        1. List'em by g3n-h@ckm@n 1.1.7.0

                          Thx to Chiquitine29.....& CCM team

                          User : dzenis (Utilisateurs) # KOSVOCORE
                          Update on 30/12/2009 by g3n-h@ckm@n ::::: 23:45
                          Start at: 20:02:33 | 01/01/2010
                          Contact : g3n-h@ckm@n sur CCM

                          Intel(R) Pentium(R) 4 CPU 2.40GHz
                          Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
                          Internet Explorer 8.0.6001.18702
                          Windows Firewall Status : Disabled

                          A:\ -> Lecteur de disquettes 3 ½ pouces
                          C:\ -> Disque fixe local | 55,87 Go (32,3 Go free) | NTFS

                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          C:\Program Files\MSI\BToes Logiciel Bluetooth\bin\btwdins.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\Program Files\MSI\BToes Logiciel Bluetooth\BTTray.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Program Files\iPod\bin\iPodService.exe
                          C:\Program Files\Java\jre6\bin\jucheck.exe
                          C:\WINDOWS\explorer.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\List_Kill'em\List_Kill'em.exe
                          C:\WINDOWS\system32\cmd.exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe
                          C:\Documents and Settings\dzenis\Local Settings\temp\2E.tmp\pv.exe

                          ======================
                          Keys "Run"
                          ======================
                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                          BluetoothAuthenticationAgent REG_SZ rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                          TkBellExe REG_SZ "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          HP Software Update REG_SZ "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                          SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
                          iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                          =====================
                          Other Keys
                          =====================
                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                          dontdisplaylastusername REG_DWORD 0 (0x0)
                          legalnoticecaption REG_SZ
                          legalnoticetext REG_SZ
                          shutdownwithoutlogon REG_DWORD 1 (0x1)
                          undockwithoutlogon REG_DWORD 1 (0x1)
                          DisableRegistryTools REG_DWORD 0 (0x0)

                          ===============
                          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                          NoDriveTypeAutoRun REG_DWORD 323 (0x143)
                          NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
                          NoDrives REG_DWORD 0 (0x0)

                          ===============
                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                          HonorAutoRunSetting REG_DWORD 1 (0x1)
                          NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
                          NoDriveTypeAutoRun REG_DWORD 323 (0x143)
                          NoDrives REG_DWORD 0 (0x0)

                          ===============
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

                          ===============
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                          ===============
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                          {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                          ===============
                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                          C:\WINDOWS\system32\sessmgr.exe REG_SZ C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019
                          C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                          %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

                          ===============
                          ActivX controls
                          ===============
                          HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{0CCA191D-13A6-4E29-B746-314DEE697D83}
                          HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}
                          HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}
                          HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8100D56A-5661-482C-BEE8-AFECE305D968}
                          HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
                          HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
                          HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}
                          HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
                          HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
                          HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
                          HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E77F23EB-E7AB-4502-8F37-247DBAF1A147}

                          ===============
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{DFB17AA8-042A-429D-987C-26CE244A4189}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                          HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

                          ==============
                          BHO :
                          ======
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

                          ================
                          Internet Explorer :
                          ================
                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                          Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                          Start Page REG_SZ https://www.google.fr/?gws_rd=ssl

                          ========
                          Services
                          ========
                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                          Ndisuio : 0x3
                          SharedAccess : 0x2
                          wuauserv : 0x2

                          =========

                          =======
                          Drive :
                          =======

                          ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                          C:\Documents and Settings\All Users.WINDOWS\Application Data\sysReserve.ini
                          C:\WINDOWS\mbr.exe
                          C:\WINDOWS\System32\drivers\etc\hosts.msn
                          C:\WINDOWS\system32\krl32mainweq.dll

                          ¤¤¤¤¤¤¤¤¤¤ Keys :

                          "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                          "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"

                          ================
                          Other infections
                          ================

                          catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2010-01-01 20:04:12
                          Windows 5.1.2600 Service Pack 2 NTFS

                          scanning hidden processes ...

                          scanning hidden services & system hive ...

                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000272c2b6c0]
                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fhvagofvw]
                          "DisplayName"="Windows Monitor"
                          "Type"=dword:00000020
                          "Start"=dword:00000002
                          "ErrorControl"=dword:00000000
                          "ImagePath"=str(2):"%SystemRoot%\system32\svchost.exe -k netsvcs"
                          "ObjectName"="LocalSystem"
                          "Description"="Autorise le téléchargement et l'installation des mises à jour de Windows. Si ce service est désactivé, cet ordinateur ne pourra pas utiliser la fonctionnalité Mises à jour automatiques, ni accéder au site Web Windows Update."

                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fhvagofvw\Parameters]
                          "ServiceDll"=str(2):"C:\WINDOWS\system32\umzqpjlg.dll"
                          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000272c2b6c0]
                          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\fhvagofvw]
                          "DisplayName"="Windows Monitor"
                          "Type"=dword:00000020
                          "Start"=dword:00000002
                          "ErrorControl"=dword:00000000
                          "ImagePath"=str(2):"%SystemRoot%\system32\svchost.exe -k netsvcs"
                          "ObjectName"="LocalSystem"
                          "Description"="Autorise le téléchargement et l'installation des mises à jour de Windows. Si ce service est désactivé, cet ordinateur ne pourra pas utiliser la fonctionnalité Mises à jour automatiques, ni accéder au site Web Windows Update."

                          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\fhvagofvw\Parameters]
                          "ServiceDll"=str(2):"C:\WINDOWS\system32\umzqpjlg.dll"

                          scanning hidden registry entries ...

                          scanning hidden files ...

                          scan completed successfully
                          hidden processes: 0
                          hidden services: 0
                          hidden files: 0

                          Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                          device: opened successfully
                          user: MBR read successfully
                          kernel: MBR read successfully
                          user & kernel MBR OK

                          ==========
                          Programs
                          ==========

                          802.11 Wireless LAN
                          Adobe
                          adslTV
                          Analog Devices
                          Apple Software Update
                          Broadcom
                          ComPlus Applications
                          DivX
                          Fichiers communs
                          Google
                          Hewlett-Packard
                          HP
                          InstallShield Installation Information
                          Internet Explorer
                          iPod
                          iTunes
                          Java
                          List_Kill'em
                          Malwarebytes' Anti-Malware
                          Microsoft CAPICOM 2.1.0.2
                          Microsoft Office
                          Microsoft Silverlight
                          Microsoft SQL Server Compact Edition
                          Microsoft Works
                          Mozilla Firefox
                          MSI
                          NetMeeting
                          OpenOffice.org 3
                          Outlook Express
                          Real
                          Services en ligne
                          Uninstall Information
                          VideoLAN
                          Windows Media Player
                          Windows NT
                          WindowsUpdate

                          ============
                          Lecteur C:
                          ============

                          AUTOEXEC.BAT
                          boot.ini
                          Bootfont.bin
                          ComboFix.txt
                          Config.Msi
                          CONFIG.SYS
                          dell
                          Documents and Settings
                          Drivers
                          IO.SYS
                          Kill'em
                          List'em.txt
                          MSDOS.SYS
                          MSOCache
                          NTDETECT.COM
                          ntldr
                          pagefile.sys
                          Program Files
                          Qoobox
                          RECYCLER
                          sqmdata00.sqm
                          sqmdata01.sqm
                          sqmdata02.sqm
                          sqmdata03.sqm
                          sqmdata04.sqm
                          sqmdata05.sqm
                          sqmdata06.sqm
                          sqmdata07.sqm
                          sqmdata08.sqm
                          sqmdata09.sqm
                          sqmdata10.sqm
                          sqmdata11.sqm
                          sqmdata12.sqm
                          sqmdata13.sqm
                          sqmdata14.sqm
                          sqmdata15.sqm
                          sqmdata16.sqm
                          sqmdata17.sqm
                          sqmdata18.sqm
                          sqmdata19.sqm
                          sqmnoopt00.sqm
                          sqmnoopt01.sqm
                          sqmnoopt02.sqm
                          sqmnoopt03.sqm
                          sqmnoopt04.sqm
                          sqmnoopt05.sqm
                          sqmnoopt06.sqm
                          sqmnoopt07.sqm
                          sqmnoopt08.sqm
                          sqmnoopt09.sqm
                          sqmnoopt10.sqm
                          sqmnoopt11.sqm
                          sqmnoopt12.sqm
                          sqmnoopt13.sqm
                          sqmnoopt14.sqm
                          sqmnoopt15.sqm
                          sqmnoopt16.sqm
                          sqmnoopt17.sqm
                          sqmnoopt18.sqm
                          sqmnoopt19.sqm
                          System Volume Information
                          WINDOWS

                          ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                          C:\dell\Drivers\R47819\Serial.mdm
                          C:\dell\Drivers\R64033\Serial.mdm

                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                          0
                          1. Contributeur sécurité
                            ▶ Relance List&Kill'em avec le raccourci sur ton bureau ,

                            mais cette fois-ci :

                            ▶ choisis l'option 2 = Mode Suppression

                            laisse travailler l'outil.

                            en fin de scan un rapport s'ouvre

                            ▶ colle le contenu dans ta reponse
                            0
                            1. Kill'em by g3n-h@ckm@n 1.1.7.0

                              User : dzenis (Utilisateurs) # KOSVOCORE
                              Update on 30/12/2009 by g3n-h@ckm@n ::::: 23:45
                              Start at: 10:04:40 | 02/01/2010
                              Contact : g3n-h@ckm@n sur CCM

                              Intel(R) Pentium(R) 4 CPU 2.40GHz
                              Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
                              Internet Explorer 8.0.6001.18702
                              Windows Firewall Status : Disabled

                              A:\ -> Lecteur de disquettes 3 ½ pouces
                              C:\ -> Disque fixe local | 55,87 Go (32,21 Go free) | NTFS

                              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\csrss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\Program Files\MSI\BToes Logiciel Bluetooth\bin\btwdins.exe
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
                              C:\WINDOWS\system32\rundll32.exe
                              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\MSI\BToes Logiciel Bluetooth\BTTray.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\WINDOWS\System32\alg.exe
                              C:\Program Files\List_Kill'em\List_Kill'em.exe
                              C:\WINDOWS\system32\cmd.exe
                              C:\WINDOWS\system32\wbem\wmiprvse.exe
                              C:\Documents and Settings\dzenis\Local Settings\temp\3.tmp\pv.exe

                              Detections :
                              ==========

                              ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                              "C:\Documents and Settings\All Users.WINDOWS\Application Data\sysReserve.ini"
                              "C:\WINDOWS\mbr.exe"
                              "C:\WINDOWS\System32\drivers\etc\hosts.msn"
                              "C:\WINDOWS\system32\krl32mainweq.dll"

                              ¤¤¤¤¤¤¤¤¤¤ Files/folders deleted :

                              Quarantine :

                              hosts.msn.Kill'em
                              krl32mainweq.dll.Kill'em
                              MBR.exe.Kill'em
                              sysReserve.ini.Kill'em

                              ==============
                              host file OK !
                              ==============

                              ========
                              Registry
                              ========
                              Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe
                              Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe

                              ============
                              Disk Cleaned
                              ============

                              ================
                              Prefetch cleaned
                              ================

                              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                              0
                              1. Non sa veut toujours pas ! Et msn ne veut toujours pas se telecharger ! Chaque fois que je click sur ton lien il me met que la page internte est impossible a ouvrir comme quand je click pour telecharger WLM ..
                                0
                                1. Contributeur sécurité
                                  ok

                                  fais ceci pour un diagnostic complet du PC :

                                  Télécharge ZHPDiag ( de Nicolas coolman ).
                                  https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

                                  Double clique sur le fichier d'installation, puis installe le avec les paramètres par défaut ( N'oublie pas de cocher " Créer une icône sur le bureau " )

                                  Lance ZHPDiag en double cliquant sur l'icône présente sur ton bureau (Clique droit -> Executer en tant qu'admin ( vista )

                                  Clique sur la loupe en haut à gauche, puis laisse l'outil scanner.

                                  Une fois le scan terminé, clique sur l'icône en forme de disquette et enregistre le fichier sur ton bureau.

                                  Rend toi sur Cjoint : http://www.cijoint.fr/

                                  Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

                                  Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

                                  Clique ensuite sur "Créer le lien cjoint " et copie/colle le dans ton prochain message
                                  0